A graphic with the title “Email Deliverability 101,” mentioning SPF, DKIM, and DMARC, with simple diagrams linking the terms. The ShortTech logo and website URL appear, along with a note on avoiding emails landing in spam.

Email Deliverability 101: SPF, DKIM and DMARC Explained

If you send email from your website or from a marketing platform, there’s a decent chance some of it is quietly landing in spam folders right now — or worse, being used by someone else to impersonate your domain. The fix isn’t complicated, but it does involve three DNS records with unhelpful acronyms: SPF, DKIM and DMARC.

Here’s what they actually do, and how to roll them out without breaking your own email in the process.

Why this matters

Every mail server checks these records before deciding whether your email lands in the inbox or the spam folder. Get them wrong and genuine mail from your website or marketing platform gets blocked, binned, or used to impersonate you. Get them right, and you protect both your deliverability and your domain’s reputation.

The three DNS records to check

SPF — Sender Policy Framework

SPF is a TXT record listing exactly which servers are allowed to send email for your domain. Anything not on that list can be rejected or flagged as suspicious.

DKIM — DomainKeys Identified Mail

DKIM adds a digital signature to your outgoing mail, so the receiving server can confirm it wasn’t altered in transit. You’ll need a separate DKIM record for each sending service you use — your website, your email marketing platform, and so on.

DMARC — Domain-based Message Authentication

DMARC tells receiving servers what to do when SPF or DKIM checks fail, and where to send reporting data about mail claiming to be from your domain. It’s the record that ties the other two together — and it’s the one most people skip.

Rolling out DMARC safely

DMARC is powerful, but jump straight to the strictest setting and you risk blocking your own genuine email. Here’s the safe way to do it:

  1. Start at p=none. This is monitor-only mode — nothing gets blocked. You just start collecting daily aggregate reports via the rua= tag.
  2. Collect for 2–4 weeks. Point rua= at a mailbox or dashboard you’ll actually check regularly.
  3. Review the reports with an AI tool. These reports arrive as raw XML, which isn’t much fun to read by hand. Drop them into the AI tool of your choice and ask it to summarise the sending sources — flag anything that looks like your domain being spoofed or used for spam.
  4. Move to p=quarantine. Once you’re confident every legitimate source is authenticated, tell servers to send failing mail to spam instead of the inbox.
  5. Move to p=reject. After a clean run at quarantine, this gives you full protection — failing mail is refused outright.

Keep it simple: none → review → quarantine → reject. Never jump straight to reject without a monitoring period first, or you risk blocking your own genuine mail.

Tools worth using

Domain Inspector

Domain Inspector gives you a free, instant snapshot of a domain’s registrar, DNS, SSL, hosting and SPF/DKIM/DMARC status. It’s a fast first check before you touch any domain’s records — including your own.

A transactional email service

For anything sent from WordPress — contact forms, order confirmations, password resets — use a dedicated transactional email service like Postmark rather than relying on your host’s shared mail server. You get a proper sending reputation, SPF/DKIM handled correctly out of the box, and delivery logs so you can actually see what happened to each message.

CleanTalk for spam-free forms

I use CleanTalk to stop spam bots submitting contact and enquiry forms on client websites. It works quietly in the background — no annoying CAPTCHAs for real visitors — and it keeps junk submissions out of your inbox (and out of your DMARC reports).

Quick checklist

  • SPF record published, listing every server that sends on your behalf
  • DKIM enabled, with a record published for each sending service
  • DMARC record published, starting at p=none with an rua= reporting address
  • Reports reviewed for 2–4 weeks (an AI tool for summarising is fine)
  • Policy tightened to p=quarantine, then eventually p=reject
  • Marketing and transactional email sent via a dedicated service, not shared hosting

Download the PDF Guide

Want help getting this set up?

This stuff is fiddly the first time you do it, and easy to get wrong in a way that quietly costs you enquiries. If you’d rather hand it over to someone who does this daily, get in touch and I’ll sort it for you.

Jas Sheridan is the founder of ShortTech, a web design and IT support studio in Chichester, West Sussex, helping small businesses with websites, hosting and everything in between.

Other Articles

A graphic with the title “Email Deliverability 101,” mentioning SPF, DKIM, and DMARC, with simple diagrams linking the terms. The ShortTech logo and website URL appear, along with a note on avoiding emails landing in spam.

Email Deliverability 101: SPF, DKIM and DMARC Explained

A hand holding a mobile phone with various app icons displayed on the screen. A blurred laptop and office environment are visible in the background.

How to Make Your iPhone Feel Brand New Again

A person wearing a light blue shirt types on a laptop at a desk. A diary, pen, and some papers are visible nearby. The scene appears to be an office or home workspace.

Inbox Overload? Here’s How to Take Back Control in 10 Minutes

Subscribe to the ShortTech Newsletter

Subscribe to be notified of new articles and other tech hints and tips.  Unsubscribe at any time 👩‍💻.